4-6
Description
Use the
dot1x authentication-method
command to set the 802.1X authentication method.
Use the
undo dot1x authentication-method
command to restore the default.
By default, CHAP is used.
z
The password authentication protocol (PAP) transports passwords in clear text.
z
The challenge handshake authentication protocol (CHAP) transports only usernames over the
network. Compared with PAP, CHAP provides better security.
z
With EAP relay authentication, the authenticator encapsulates 802.1X user information in the EAP
attributes of RADIUS packets and sends the packets to the RADIUS server for authentication; it
does not need to repackage the EAP packets into standard RADIUS packets for authentication. In
this case, you can configure the
user-name-format
command but it does not take effect. For
information about the
user-name-format
command, refer to
AAA Commands
in the
Security
Volume
.
Note that:
z
Local authentication supports PAP and CHAP.
z
For RADIUS authentication, the RADIUS server must be configured accordingly to support PAP,
CHAP, or EAP authentication.
Related commands:
display dot1x
.
Examples
# Set the 802.1X authentication method to PAP.
<Sysname> system-view
[Sysname] dot1x authentication-method pap
dot1x guest-vlan
Syntax
In system view:
dot1x guest-vlan guest-vlan-id
[
interface
interface-list
]
undo dot1x guest-vlan
[
interface
interface-list
]
In interface view:
dot1x guest-vlan guest-vlan-id
undo dot1x guest-vlan
View
System view, Layer 2 Ethernet interface view
Default Level
2: System level
Parameters
guest-vlan-id
: ID of the VLAN to be specified as the guest VLAN, in the range 1 to 4094. It must
already exist.
Содержание E4510-48G
Страница 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Страница 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Страница 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Страница 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Страница 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Страница 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Страница 857: ...iii 7 Track Configuration Commands 7 1 Track Configuration Commands 7 1 display track 7 1 track nqa 7 2 ...
Страница 914: ...5 17 Sysname reset oam ...
Страница 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Страница 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...